Getting Data In

Peer sends acknowledgment whether fulfil replication factor when forwarder is mAck=true

Wenjian_Zhu
Explorer

Dear splunkers,

When set useAck = true (https://docs.splunk.com/Documentation/Splunk/9.4.0/Forwarding/Protectagainstlossofin-flightdata).

The source peer sends acknowledgment after writing the data to its file system and ensuring the replication factor is met 

or

The source peer sends acknowledgment after writing the data to its file system.

 

Best regards,

Labels (2)
0 Karma
1 Solution

isoutamo
SplunkTrust
SplunkTrust

Actually it needs that replication factor has met on indexers before the ack has sent.

You should read below post and also those where are linked there.


Here is one old excellent post about it https://community.splunk.com/t5/Knowledge-Management/Splunk-Indexer-Forwarder-Acknowledgement-explai...

View solution in original post

isoutamo
SplunkTrust
SplunkTrust

Actually it needs that replication factor has met on indexers before the ack has sent.

You should read below post and also those where are linked there.


Here is one old excellent post about it https://community.splunk.com/t5/Knowledge-Management/Splunk-Indexer-Forwarder-Acknowledgement-explai...

Wenjian_Zhu
Explorer

Hi @isoutamo ,

Thx a lot 👍.

BR

0 Karma

SanjayReddy
SplunkTrust
SplunkTrust

Hi @Wenjian_Zhu 

 Indexer acknowledgment will be sent after data written into the disk of indexer. 

there is no relation with data replication with indexer acknowledgment

acknowledgment is to let forwarders know data has been received at the indexer end and forwarder which sent data to indexer , will remove the events from the wait queue.

also recommended to enable   acknowledgment at at intermediate forwader and indexer 

SanjayReddy_0-1738418106233.png

 

Wenjian_Zhu
Explorer

Hi @SanjayReddy 

Thanks for the feedback, that screenshot is when receiver is a forwarder.

This is a good explanation https://community.splunk.com/t5/Knowledge-Management/Splunk-Indexer-Forwarder-Acknowledgement-explai... as @isoutamo mentioned.

Thanks. 

0 Karma
Career Survey
First 500 qualified respondents will receive a $20 gift card! Tell us about your professional Splunk journey.

Can’t make it to .conf25? Join us online!

Get Updates on the Splunk Community!

Take Action Automatically on Splunk Alerts with Red Hat Ansible Automation Platform

 Are you ready to revolutionize your IT operations? As digital transformation accelerates, the demand for ...

Calling All Security Pros: Ready to Race Through Boston?

Hey Splunkers, .conf25 is heading to Boston and we’re kicking things off with something bold, competitive, and ...

Beyond Detection: How Splunk and Cisco Integrated Security Platforms Transform ...

Financial services organizations face an impossible equation: maintain 99.9% uptime for mission-critical ...